coheigea commented on code in PR #3530:
URL: https://github.com/apache/cxf/pull/3530#discussion_r4146174969


##########
rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/JwtAccessTokenValidator.java:
##########
@@ -51,6 +51,7 @@ public class JwtAccessTokenValidator extends JoseJwtConsumer 
implements AccessTo
 
     private Map<String, String> jwtAccessTokenClaimMap;
     private boolean validateAudience = true;
+    private boolean requireAudience;

Review Comment:
   Yes, requireAudience only takes effect when validateAudience is enabled (the 
default). Both flags go into JwtUtils.validateTokenClaims, and requireAudience 
just decides what happens in the "no aud claim" branch of the audience 
restriction check, which isn't reached when validateAudience is false. So:
   
   - validateAudience=true, requireAudience=false (defaults): a token without 
aud is accepted; if aud is present it must match the expected audience or the 
request URL.
   - validateAudience=true, requireAudience=true: a token without aud is 
rejected; otherwise same as above.
   - validateAudience=false: no audience checks at all, whatever 
requireAudience is set to.
   
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to